SAP security note 2488516, “Cross-Site Scripting (XSS) vulnerability in Web Dynpro ABAP”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Web Dynpro ABAP does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability. This can allow attackers to deface content, steal user session information, or impersonate users.
Solution
The vulnerability is resolved by updating the Unified Rendering part of Web Dynpro ABAP as described in SAP Note 2090746 (“Unified Rendering Update – Instructions and Related Notes”) or by importing the relevant Support Package (e.g., SAPKB73121 for SAP_BASIS release 731).
CVSS
Score 6.1 Vector: AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References
Affected components
- SAP_UI 740, 750, 751
- SAP_BASIS 702, 730, 731
Full note on SAP: SAP Support Launchpad note 2488516
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



